Brief Insights

  • The cybersecurity industry widely focuses on how AI helps hackers analyze vulnerabilities faster and craft more sophisticated malware, but a new report points out that AI's enhanced ability to imitate corporate leadership is equally far-reaching.
  • A report released on June 4 by security firm Outtake shows that this year, more than half (53%) of organizations have experienced impersonation attacks targeting executives or frontline employees.
  • The report also found that three-quarters of surveyed companies only conduct limited impersonation monitoring or respond passively when attacks occur.

Deep Analysis

AI's ability to generate realistic fake media has opened a "second battlefield" for enterprises against impersonation scams. Outtake, based on a survey of over 1,100 cybersecurity and risk management leaders, notes in its report that AI-generated deepfake content has made identity impersonation of corporate leadership more covert and dangerous.

The report shows that nearly half (47%) of companies "have experienced confirmed or suspected synthetic media impersonation incidents involving executives or brand representatives." Additionally, companies view AI-generated attacks as the biggest visibility blind spot in their anti-impersonation strategies.

"People are the attack surface with the largest exposure and the weakest protection," Outtake emphasizes in the report. However, only 43% of companies conduct identity forgery simulation exercises for executives to identify potential major impersonation risks.

In terms of agent technology, companies are equally underprepared in AI threat protection. Outtake found that companies generally fail to effectively supervise and protect these agents, amplifying the risk of agent hijacking attacks that could damage corporate reputation or financial security. Only 4% of companies said they have implemented comprehensive monitoring and control over AI agents.

The report gives an example: an AI agent in the finance department receives what appears to be a routine payment inquiry email, but the email contains hidden code that overrides the agent's original programming, forcing it to leak information to an untrusted third party.

"The agent now sits at a new trust boundary: one foot in the untrusted external world, the other in trusted internal systems," Outtake points out. "The implanted instructions cross that boundary."

The report also finds that governance fragmentation is another major weakness for companies. In 21% of companies, no team is specifically responsible for assessing and managing digital trust risks; 18% assign this to security operations centers, 13% to fraud and security teams, and 11% to threat intelligence teams. Over 60% of companies say their digital trust risk management activities are fragmented and siloed.